SB2021090908 - Multiple vulnerabilities in Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers
Published: September 9, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2021-34708)
The vulnerability allows a local administrator to execute arbitrary code on the system.
The vulnerability exists due to an unsigned script within the ISO that is not verified when the install request is being processed. A local administrator can modify an ISO image and execute arbitrary code on the affected device.
2) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2021-34709)
The vulnerability allows a local administrator to execute arbitrary code on the system.
The vulnerability exists in the Cisco IOS XR due to a race condition that occurs when the install request is being processed. A local administrator can modify an ISO image and execute arbitrary code on the affected device.
Remediation
Install update from vendor's website.